When Responsible Disclosure Becomes a Criminal Investigation: Uncovering CVE-2025-43928 in Law Enforcement Surveillance Systems
In late 2024, we discovered a critical path traversal vulnerability (CVE-2025-43928) affecting Media Relay Service (MRS), a software platform used worldwide in surveillance and reconnaissance systems manufactured by Infodraw. The affected ecosystem includes mobile video surveillance solutions, police body cameras, covert observation equipment, and drone-based reconnaissance platforms operated by law enforcement agencies and governmental organizations - including the Unité Spéciale de la Police in Luxembourg.
The vulnerability allowed unauthenticated attackers to access arbitrary files on affected Windows and Linux systems and, under certain circumstances, delete files remotely. Through internet-wide scanning and coordinated vulnerability disclosure efforts, vulnerable systems were identified across multiple countries, including systems attributed to specialized police units and operational surveillance teams.
This presentation will cover the technical analysis of the vulnerability, the methodology used to identify exposed systems, challenges encountered during responsible disclosure when the vendor remained unresponsive, and the coordination with national CERTs and affected operators. The talk will further discuss how a successful disclosure process ultimately resulted in a criminal investigation (in Luxembourg) against the reporting researcher, despite the affected system being secured following notification.
Using this case study, we will examine the growing tension between cybersecurity research, public-interest vulnerability disclosure, law enforcement operations, and outdated computer crime legislation. The presentation aims to provide practical lessons for vulnerability researchers, CERT teams, and policymakers while highlighting the need for legal certainty for security research in Europe.
More information:
English: https://mint-secure.de/path-traversal-vulnerability-in-surveillance-software/
German: https://mint-secure.de/ermittlungsverfahren-nach-meldung-von-it-sicherheitsluecken-in-observationssystemen/
German: https://mint-secure.de/path-traversal-sicherheitsluecke-aufklaerungsgeraete/
The talk begins with a technical deep dive into CVE-2025-43928, a path traversal vulnerability in Infodraw's Media Relay Service (MRS). We will demonstrate how a flawed authentication mechanism and insecure file handling enabled arbitrary file access and deletion through crafted username parameters.
Internet-Wide Exposure Assessment
Following vulnerability discovery, internet-wide scans were conducted to identify exposed deployments. We will discuss:
- Detection methodology
- Challenges when systems are not indexed by common search engines such as Shodan
Attribution of exposed systems - Operational considerations when dealing with government-operated infrastructure
From Hall of Fame to Criminal Investigation
One of the most unusual aspects of this case occurred after disclosure. Following successful notification of a vulnerable law enforcement system and acknowledgement by a national GovCERT, a criminal investigation was initiated against the reporting researcher. Later this investigation was closed.
This section discusses:
- Legal risks facing security researchers
- Cross-border disclosure challenges within Europe
- Conflicts of interest involving government-operated systems
- Current shortcomings of computer crime legislation
- Recommendations for creating legal certainty for good-faith security research
Attendees will leave with:
- A real-world case study involving surveillance technology used by law enforcement agencies
- Practical guidance for handling large-scale coordinated disclosure efforts
- Lessons learned from interacting with CERTs, vendors, and government organizations
- Insights into the legal challenges facing vulnerability researchers across Europe
- Recommendations for improving vulnerability disclosure ecosystems and researcher protections
Founder & CEO of Mint Secure GmbH: https://mint-secure.de/
Member of Chaos Computer Club and OWASP
Protecting what matters in a connected world